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IN THE CLAIMS: 

Please amend the claims as follows: 

20. (Currently Amended) A method for policy-based billing for a distributed network 
session, comprising; 

(a) receiving a plurality of packets at a plurality of analyzers; 

(b) aggregating the pluraHty of packets; 

(c) analyzing the plurality of packets to identify a plurality of flows; 

(d) identifying a session associated with the flows; 

(e) identifying at least one application associated with the session; 

(f) reconstructing the session utilizing the identified application , the session 
reconstruction being carried out at a plurality of collaborating nodes; 

(g) identifying a user associated with the session; 

(h) determining a policy; and 

(i) billing the user for the session in accordance with the policy; 
wherein th e session reconstruction is performed at a first analyzer, and 

upon a successful session reconstruction on the first analyzer, a first 
message is s ent to at least one second analyzer separate from the first analyzer, the 
first message corresponding to session data, and 

upon an unsuccessful session reconstruction on the first analyzer, one or 
more mess ages is sent to the second analyzer, the one or more messages including 
unrecognized data . 

21 . (Original) The method as reched in claim 20, and further comprising filtering the 
packets for removing packets unrelated to the session. 

22. (Original) The method as recited in claim 20, and further comprising identifying 
application events associated with the session based on the policy. 
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23. (Original) The method as recited in claim 22, and further comprising assigning a 
significance to the application events based on the policy. 

24. (Original) The method as recited in claim 22, wherein the user is billed for the 
session utilizing the application events in accordance witli the policy. 

25. (Original) The method as recited in claim 22, and ftirther comprising determining 
billing information for the session using the application events in accordance with the 
policy. 

26. (Original) The method as recited in claim 25, and further comprising outputting a 
report including the billing information in accordance with the policy. 

27. (Original) The method as recited in claim 20, and further comprising restricting 
tasks of the user in accordance with the policy. 

28. (Original) The method as recited in claim 27, wherein an amount of bandwidth is 
restricted in accordance with the policy. 

29. (Original) The method as recited in claim 20, wherein the policy includes a series 
of packet capture language expressions and output selectors. 

30. (Currently Amended) A computer program product for policy-based billing for a 
distributed network session, comprising: 

(a) computer code for receiving a plurality of packets at a plurality of analyzers; 

(b) computer code for aggregating the plurality of packets; 

(c) computer code for analyzing the pluralit>' of packets to identify a plurality of 
flows; 

(d) computer code for identifying a session associated wdth the flows; 

(e) computer code for identifying at least one application associated with the session; 
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(f) computer code for reconstructing the session utilizing the identified application. 
the session reconstruction being carried our 2i plurality of collaborating nodes; 

(g) computer code for identifying a user associated with the session; 

(h) computer code for determining a policy; and 

(i) computer code for billing the user for the session in accordance with the policy; 
wherein the session recons taiction is p e rformed at a first analyzer, and 

upon a successfiil session rec onstruction on the first analyzer, a first 
message is sent to at least one second ana lyzer separate from the first analyzer, the 
first messa ge corresponding to session data, and 

upon an unsuccessful s ession reconstruction on the first analyzer, one nr 
more me ssages is sent to the second analyzer, the one or more messages including 
unrecognized data . 

31. (Original) The computer program product as recited in claim 30, and flirther 
comprising computer code for filtering the packets for remoying packets unrelated to the 
session. 

32. (Original) The computer program product as recited in claim 30, and further 
comprising computer code for identifying application eyents associated with the session 
based on the policy. 

33. (Original) The computer program product as recited in claim 32, and fiirther 
comprising computer code for assigning a significance to the application events based on 
the policy. 

34. (Original) The computer program product as recited in claim 32, wherein the user 
is billed for the session utilizing the application events in accordance with the policy. 

35. (Original) The computer progrmn product as recited in claim 32, and further 
comprising computer code for determining billing information for the session using the 
application events in accordance witli the policy. 
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36. (Original) The computer program product as recited in claim 35, and further 
comprising computer code for outpulting a report including the billing information in 
accordance with the policy. 

37. (Original) The computer program product as recited in claim 30, and further 
comprising computer code for restricting tasks of the user in accordance with the policy. 

38. (Original) The computer program product as recited in claim 37, wherein an 
amount of bandwidth is restricted in accordance with the policy. 

39. (Original) The computer program product as recited in claim 30, wherein the 
policy includes a series of packet capture language expressions and output selectors. 

40. (Currently Amended) A method for policy-based billing for a distributed network 
session, comprising: 

(a) receiving a plurality of packets at a plurality of analyzers; 

(b) aggregating the plurality of packets; 

(c) analyzing the plurality of packets to identify at least a first flow; 

(d) identifying a session associated with the first flow; 

(e) identifying additional flows in the plurality of packets associated with the session; 

(f) filtering the packets for removing packets unrelated to the session; 

(g) identifying at least one application associated with the session; 

(h) reconstructing the session utilizing the identified application , the session 
reconstruction being carried out at a plurality of collaborating nodes; 

(i) identifying a user associated with the session; 
(j) identify'ing a policy; 

(k) gathering application events associated with the session based on the policy; 
(1) assigning a significance to the application events based on the policy; 
(m) determining billing information for the session using the application events in 
accordance with the policy; 
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(n) outputting a report including the billing information in accordance with the policy; 

(o) restricting tasks of the user in accordance with the policy; and 

(p) executing actions in response to the application events in accordance with the 

policy; 

wherein the session reconstruction is performed at a first analyzer, and 

upon a successful session reconstruction on the first analvzen a first 

message is sent to at least one second analyzer separate from the first analyzer, the 

first message corresponding to session data, and 

upon an unsuccessful session reconstruction on the first analyzer, one or 

more messages is sent to the second analyzer, the one or more messages including 

unrecognized data . 

41 . (Previously Added) The metliod as recited in claim 20, wherein a first flow 
associated with a first application flows through a first one of the nodes. 

42. (Previously Added) The method as recited in claim 41, w^herein a second flow 
associated with the first application Hows through a second one of the nodes. 

43. (Previously Added) The metliod as recited in claim 20, wherein each of the 
collaborating nodes includes a packet source and a first hierarchical network analyzer. 

44. (Previously Added) The method as recited in claim 43, wherein each of the 
collaborating nodes further includes a filter coupled between the packet source and the 
first hierarcliical network analyzer. 

45. (Previously Added) The method as recited in claim 43, wherein the first 
hierarchical network analyzers of each of the nodes feed information to a second 
hierarchical network analyzer. 
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46. (Previously Added) The method as recited m claim 45, wherein the information h 
used by the second hierarchical network analyzer to reconstruct the session utilizing the 
identified application. 

47. (Previously Added) The method as recited in claim 45, wherein the information 
involves packet forwarding. 

48. (Currently Amended) The method as recited in claim 45, wherein the information 
involves hints and packet forwarding, the hints being generated by a lower level session 
analyzer and provided to a higher level analvzer to facilitate the reconstruction of the 
session. 

49. (Currently Amended) The method as recited in claim 45, wherein the information 
involves hints and a summary of packets , the hints being generated bv a lower level 
session a nalvzer and provided to a higher level analvzer to facilitate the reconstruction of 
the session. 



50. (Previously Added) The methud as recited in claim 20, wherein the nodes each 
include a router. 
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